BitDefender spotlights piracy as the weak link of on-line safety

1 April 2011 Information Security

The malware charts for the first quarter of the year sees malware related to software piracy ranking high, as outlined by the BitDefender antimalware intelligence data. The Autorun function of removable devices still remains the number one vulnerability exploited by cybercriminals; and illegal advertising holds on to an ‘honourable’ and steady fourth place in the Q1 2011 e-threat top.

Malware distribution for January - March 2011:

On the highest position in the e-threat distribution chart at the end of Q1, 2011 BitDefender spots Trojan.AutorunINF.Gen that accounts for a percentage of 7,26 from the total amount of detections worldwide. This makes the autorun function of the removable devices vulnerable to malware attacks of all kinds. The constant presence of the worm in BitDefender’s top 5 malware reveals that users are still reluctant to installing security updates from the operating system vendor.

Trojan.Crack.I accounting for a percentage of 6,07 points ranks second after only a few months of existence. It should be mentioned that this application generates unauthorised registration keys in order to defeat the commercial protection of shareware software products. It may also try to collect details about further applications that run on the compromised computer (name, version, registration keys etc,) and send them to a remote attacker who would subsequently sell these licenses as OEM Software.

Win32.Worm.Downadup.Gen ranks third with 5,58% from the total number of infections registered worldwide this first quarter of 2011. There are countries like the United Kingdom where this malware saw a significant drop in detection, but there are other regions where it still dominates the malware charts (like Romania and Spain). This worm’s agenda is well-known by now: amongst others, it prevents users from accessing both Windows Update and security vendors’ web pages, while also downloading rogue AVs on the compromised computers.

Gen:Variant.Adware.Hotbar.1 accounts for 4,85% of the total amount of malware which places it fourth in this year’s quarterly malware distribution chart. Gen:Variant.Adware.Hotbar.1 forces pop-up messages on users’ PC screens, while also initiating new browser windows usually located on the right side of the desktop. This family of malware is also capable of browser hijacking, which means that most of the search queries will be routed to various ad campaigns which boost the attacker’s advertising revenue. This adware tool can be used to gather data on the surfers’ habits in order to serve targeted ads or shopping suggestions.

The fifth place in this quarterly malware top goes to Exploit.CplLnk.Gen - a detection specific to lnk files (shortcut files) that makes use of a vulnerability in the Windows OSes to execute arbitrary code. This exploit has seen a significant boost these past few weeks and it is expected to spread even further. It is also one of the four zero-day exploits that have been intensively used by the Stuxnet worm to compromise local security.





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Cybersecurity and AI
AI & Data Analytics Information Security
Cybersecurity is one of the primary reasons that detecting the commonalities and threats of what is otherwise completely unknown is possible with tools such as SIEM and endpoint protection platforms.

Read more...
What are MFA fatigue attacks, and how can they be prevented?
Information Security
Multifactor authentication is a security measure that requires users to provide a second form of verification before they can log into a corporate network. It has long been considered essential for keeping fraudsters out. However, cybercriminals have been discovering clever ways to bypass it.

Read more...
SA's cybersecurity risks to watch
Information Security
The persistent myth is that cybercrime only targets the biggest companies and economies, but cybercriminals are not bound by geography, and rapidly digitising economies lure them in large numbers.

Read more...
Cyber insurance a key component in cyber defence strategies
Information Security
[Sponsored] Cyber insurance has become a key part of South African organisations’ risk reduction strategies, driven by the need for additional financial protection and contingency plans in the event of a cyber incident.

Read more...
Deception technology crucial to unmasking data theft
Information Security Security Services & Risk Management
The ‘silent theft’ of data is an increasingly prevalent cyber threat to businesses, driving the ongoing leakage of personal information in the public domain through undetected attacks that cannot even be policed by data privacy legislation.

Read more...
Data security and privacy in global mobility
Security Services & Risk Management Information Security
Data security and privacy in today’s interconnected world is of paramount importance. In the realm of global mobility, where individuals and organisations traverse borders for various reasons, safeguarding sensitive information becomes an even more critical imperative.

Read more...
Sophos celebrates partners and cybersecurity innovation at annual conference
News & Events Information Security
[Sponsored] Sun City hosted Sophos' annual partner event this year, which took place from 12 to 14 March. Sophos’ South African cybersecurity distributors and resellers gathered for an engaging two-day conference.

Read more...
The CIPC hack has potentially serious consequences
Editor's Choice Information Security
A cyber breach at the South African Companies and Intellectual Property Commission (CIPC) has put millions of companies at risk. The organisation holds a vast database of registration details, including sensitive data like ID numbers, addresses, and contact information.

Read more...
Navigating South Africa's cybersecurity regulations
Sophos Information Security Infrastructure
[Sponsored] Data privacy and compliance are not just buzzwords; they are essential components of a robust cybersecurity strategy that cannot be ignored. Understanding and adhering to local data protection laws and regulations becomes paramount.

Read more...
AI augmentation in security software and the resistance to IT
Security Services & Risk Management Information Security
The integration of AI technology into security software has been met with resistance. In this, the first in a series of two articles, Paul Meyer explores the challenges and obstacles that must be overcome to empower AI-enabled, human-centric decision-making.

Read more...